Privacy Policy
Last updated: September 11, 2026
This privacy policy covers the Curtis Salinger Photography website (curtissalinger.com), the iOS app, and the Android app (together, the "Service"). The short version: the Service does not sell personal information, use advertising trackers, or follow you across apps or websites. The iOS app sends the limited anonymous usage events described below, and the apps send an anonymous push-notification token if you opt in to notifications.
Information We Collect
There are no accounts, sign-ups, advertising trackers, or third-party analytics tools. We do not ask for your name, email, phone number, or any other identifying information in order to use the Service. The limited data sent by the iOS app is described in "Anonymous iOS Analytics" and "Push Notifications" below.
Anonymous iOS Analytics
The iOS and iPadOS app records four kinds of product-interaction events: a cold app start, a return after the app was continuously in the background for at least 30 minutes, opening an album, and opening an album or flight announcement by tapping its notification. We use these events only to understand app and content engagement and to improve the Service. The website, Android, Apple TV, and Apple Vision apps are not included in this analytics collection.
Each event contains a random event ID used only to prevent duplicate uploads, the event type, the time it occurred, the iOS platform, app version and build, whether it came from the owner's validated device, and—when applicable—the album slug or notification-delivery ID. We do not store an install or device identifier, push token, IP address, or user agent with an analytics event, so separate events cannot be tied to one person or installation.
Analytics events are processed and stored by Cloudflare on our behalf and are permanently deleted after 90 days. Activity from the owner's validated device is excluded from reporting by default. Activity sent before that device is validated cannot be identified or removed retroactively.
Push Notifications
If you grant the iOS or Android app permission to send notifications, your device generates an anonymous push token (an APNs token on iOS, an FCM token on Android). The app sends this token to our server so that we can deliver notifications when new photos, albums, or flight paths are posted. The token cannot be used to identify you personally — it identifies a specific app install on a specific device, and it rotates if you reinstall the app.
Tokens are stored on our server (Cloudflare) for as long as your install is active. They are automatically removed when Apple's or Google's push services tell us a token is no longer valid (for example, because you uninstalled the app or revoked notifications). You can revoke notifications at any time in your device's system settings, which also stops the token from being usable.
Apple Push Notification service (Apple) handles delivery on iOS; Firebase Cloud Messaging (Google) handles delivery on Android. We do not send these services any information about you beyond what is required to route the notification to your device.
App Permissions
The iOS and Android apps may request the following permissions. With the analytics and notification data described above, data covered by these permissions stays on your device and is never transmitted to us or to any third party.
- Notifications: Lets us tell you when new photos, albums, or flight paths are posted. See the "Push Notifications" section above for the only piece of data this sends to us.
- Save to Photos / Photo Library: Only used when you choose to save a watermarked photo to your camera roll or gallery. We do not read photos from your library.
- Favorites: When you favorite a photo, that preference is saved in the app's local storage on your device. It is not synced to any server and is removed when you delete the app.
Photo Content
The apps and website display photographs hosted by Curtis Salinger Photography. Loading these images requires your device to make standard network requests, which, like any web request, include your IP address and user agent. We do not log or analyze this data for tracking purposes. The Android app uses the Google Maps SDK to render the photo-locations map; map tile requests are sent to Google on your device, subject to Google's privacy policy.
Private Client Galleries
Some galleries are password-protected. When you enter a password, it is sent over HTTPS to verify access. We do not store the passwords you type. To protect against brute-force attempts, the server temporarily uses your IP address for rate limiting; this data is not used for any other purpose and is not shared.
Third Parties
We do not sell, rent, or share information with third parties for marketing or analytics purposes. We rely on the following service providers to deliver the Service:
- Cloudflare: Hosts the website and apps' backend and stores the anonymous iOS analytics events for up to 90 days. Cloudflare may also process standard network-level information (such as IP addresses) while delivering content and protecting against abuse, but we do not place that information in analytics event records.
- Apple (APNs): Delivers push notifications to iOS devices.
- Google (Firebase Cloud Messaging, Google Maps SDK): Delivers push notifications to Android devices and renders the photo-locations map on Android.
Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone, including children.
Changes to This Policy
If this policy ever changes, the updated version will be posted on this page with a new "Last updated" date.
Contact
Questions about this policy? Reach out at hello@curtissalinger.com .